Vulnerabilities > Maarch > Letterbox

DATE CVE VULNERABILITY TITLE RISK
2015-02-19 CVE-2015-1587 Arbitrary File Upload vulnerability in Maarch Gec/Ged and Letterbox
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename in tmp/.
network
low complexity
maarch
7.5
2014-11-20 CVE-2014-8995 SQL Injection vulnerability in Maarch Letterbox 2.8
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
network
low complexity
maarch CWE-89
5.0